CVE-2022-34618: XSS
Published Aug 2, 2022
·Updated
A stored cross-site scripting (XSS) vulnerability in Mealie 1.0.0beta3 allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the recipe description text field.
Affected Software
1 affected component
Mealie Project Mealie=1.0.0-beta3
Event History
Aug 2, 2022
CVE Published
via MITRE·03:00 PM
Data Sourced
via MITRE·03:00 PM
Description
Frequently Asked Questions
1
What is the CVE ID of this vulnerability?
The CVE ID of this vulnerability is CVE-2022-34618.
2
What is the severity of CVE-2022-34618?
The severity of CVE-2022-34618 is medium with a CVSS score of 5.4.
3
What is the affected software?
The affected software is Mealie 1.0.0beta3.
4
What can an attacker do with this vulnerability?
An attacker can execute arbitrary web scripts or HTML via a crafted payload injected into the recipe description text field.
5
Is there a fix available for this vulnerability?
Yes, a fix is available for this vulnerability. It is recommended to update to a version higher than 1.0.0-beta3.